audit

package
v1.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Overview

Package audit appends a structured record of every validation to a JSONL audit log. Records contain only the SHA-256 hash of the key, never the raw secret, so the audit log is safe to ship alongside other operational logs.

Each line is a JSON object:

{"ts":"2026-...","provider":"openai","key_sha256":"...","is_valid":true,
 "status_code":200,"error_code":"","duration_ms":123}

The file is opened once per write and held until Close(); concurrent Emit calls are serialized through an internal mutex.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DefaultPath

func DefaultPath() string

DefaultPath returns the conventional audit log location: ~/.kunji/audit.jsonl (override with KUNJI_AUDIT_FILE).

func HashKey

func HashKey(key string) string

HashKey returns the SHA-256 hex digest of the key. Exposed so callers (and tests) can reproduce the audit hash independently.

Types

type Logger

type Logger struct {
	// contains filtered or unexported fields
}

Logger is the audit writer. A nil Logger is a valid no-op (Emit returns nil and Close returns nil) so callers don't need to nil-check.

func Open

func Open(path string) (*Logger, error)

Open creates or appends to the audit log at path. Missing parent dirs are created with 0700 perms. If path == "", a no-op Logger is returned.

func (*Logger) Close

func (l *Logger) Close() error

Close flushes and closes the underlying file. Idempotent.

func (*Logger) Emit

func (l *Logger) Emit(r *models.ValidationResult) error

Emit writes one audit record. Safe for concurrent use. A nil receiver is a no-op so callers don't need to guard.

func (*Logger) Path

func (l *Logger) Path() string

Path returns the on-disk path of the audit log (or "" for the no-op logger).

type Record

type Record struct {
	Timestamp  string `json:"ts"`
	Provider   string `json:"provider"`
	KeySHA256  string `json:"key_sha256"`
	IsValid    bool   `json:"is_valid"`
	StatusCode int    `json:"status_code,omitempty"`
	ErrorCode  string `json:"error_code,omitempty"`
	DurationMs int64  `json:"duration_ms,omitempty"`
}

Record is one line in the audit log.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL